Cybertrust Japan SecureSign root inclusion request for CA12, CA14, and CA15
This case is a Mozilla CA Program root inclusion request for Cybertrust Japan’s SecureSign Root CA12, CA14, and CA15. The request was linked to CCADB Case 585 and moved through audit review, self-assessment review, and public discussion before approval. Cybertrust Japan said its point-in-time audit was delayed by COVID-19, then later provided audit statements, CP/CPS updates, and CA compliance self-assessment materials. Mozilla noted that the request entered the 6-week public discussion period on 2024-05-10, then a 7-day last-call period on 2024-07-08. On 2024-07-15, Mozilla approved the roots for the websites trust bit with EV enablement, and on 2024-08-28 Mozilla noted the roots were in NSS 3.104 and Nightly 131.0a1. The bug is resolved as FIXED.
- Mozilla opened a root inclusion request for SecureSign Root CA12, CA14, and CA15.
- Mozilla approved the three roots for the websites trust bit with EV enablement.
- Mozilla noted the roots were included in NSS 3.104 and Nightly 131.0a1.
- Mozilla representative — Mozilla said the request was in CCADB as Case 585 and linked the public CCADB case URL.
- SECOM Trust Systems CO., LTD. — Cybertrust Japan said its point-in-time audit for the new roots was delayed by COVID-19 and would be available by the end of September.
- Mozilla representative — Mozilla asked for status on the audit reports and said a Baseline Requirements self-assessment was also needed.
- Mozilla representative — Mozilla said audits and updated CP/CPS had been received, but a compliance self-assessment was still needed.
- SECOM Trust Systems CO., LTD. — Cybertrust Japan uploaded a CA Compliance Self Assessment spreadsheet.
- Mozilla representative — Mozilla uploaded a reviewed version of Cybertrust Japan’s compliance self-assessment based on CP version 1.15 and CPS version 1.04.
- SECOM Trust Systems CO., LTD. — Cybertrust Japan responded to Mozilla’s reviewer comments and said it would update its CP/CPS within about a week.
- Mozilla representative — Mozilla said the request entered the 6-week public discussion period on 2024-05-10.
- Mozilla representative — Mozilla said the public discussion ended and a 7-day last-call for comments began.
- Mozilla representative — Mozilla approved the inclusion request for SecureSign Root CA12, CA14, and CA15 for the websites trust bit with EV enablement.
- Mozilla representative — Mozilla said the roots were now in NSS 3.104 and Nightly 131.0a1.